Created on
09-04-2023
10:02 PM
Edited on
09-05-2023
08:23 AM
By
Nishtha_Baria
Description |
This article discusses when FortiGate is not able to send logs to FortiAnalyzer with FIPS -CC mode enabled in version 7.2.5. |
Scope | FortiGate v7.2.5. |
Solution |
For versions 7.2.5 and 7.4.0, FIPS FortiGate will do the FortiAnalyzer certificate check. The following error will appear in OFTP debugs on FortiGate:
There are some configuration changes required on both FortiGate and FortiAnalyzer:
Here is the requirement for the certificate: In v7.2.5 the OFTP certificate check has changed. FortiAnalyzer and FIPS-CC mode FortiGate each need to have a certificate signed by the same CA.
CA cert requirement:
FortiGate cert requirement:
Here is configuration example:
config log fortianalyzer setting set status enable set server "faz.domain.com" set certificate-verification disable set serial "FAZ-VM0000xxxxxx" set certificate "FIPS-FGT-Cert" set upload-option realtime
config system certificate oftp set mode local set local "FAZ-Cert" end
After changing the OFTP setting on FortiAnalyzer, it is necessary to restart the daemon using the command 'diag test application oftpd 99'. If it still does not work, try to change the FortiGate certificate to a wildcard certificate. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.